Documentation Center
AlienVault® USM Anywhere™

Scheduling a Forensics and Response Job

  Role Availability   Read-Only   Analyst   Manager

The AlienApp for Forensics and Response page provides easy access to define a scheduled job to retrieve your Windows or Linux system data. You can also create a scheduled job to execute system-level enforcement functions on Windows hosts, such as Shutdown, Restart, and Stop Process. Review the information in Supported Actions to determine the action that you want to use for your scheduled job.

After you create the new job, you can make changes to the parameters for the scheduled job or review its history in the Scheduler page. For more information about working with scheduled jobs, see Managing Jobs in the Scheduler.

To schedule a Forensics and Response job

  1. In USM Anywhere, go to DATA SOURCES > INTEGRATIONS.
  2. Click the AlienApps tab.

    Access the AlienApps page

  3. In the AlienApps page, click the Forensics and Response tile.

    Click the Forensics & Response tile

  4. If you have more than one deployed USM Anywhere Sensor, select the Sensor that you want to use to run the Forensics and Response action.

    This should be the Sensor that is associated with the asset that you want to specify as the target for the action.

    Select a deployed sensor used to run the app

  5. Select the ACTIONS tab.

  6. On the right side of the page, click Schedule Job.

    Add a scheduled job for the AlienApp for Forensics and Response

    This opens the Schedule New Job dialog with many of the options already defined for the Forensics and Response app job.

  7. Enter the Name and Description for the job.

    The description is optional, but it is a best practice to provide this information so that others can easily understand what it does.

  8. Click the App Action list and select the command you want to run for the asset.

    Select the app action to run for the Forensics and Response app job

  9. Specify the Asset that you want to use as a target for the action.

    You can start typing the name or IP address of the asset in the field to display matching items that you can select. Or you can click the Browse Assets link to open the Select Asset dialog and browse the asset list to make your selection.

  10. (Optional) Set the required parameters.

    Some enforcement actions take one or more parameters in order to execute to system function on the target system. If you need more information about these parameters for a specific function, see Enforcement System Functions.

  11. Set the Schedule to specify when USM Anywhere runs the job.

    First, choose the increment as Hour, Day, Week, Month, or Year. Next, set the interval options for the increment. The selected increment determines the available options.

    For example, on a weekly increment you can select the days of the week to run the job.

    Set the schedule for the job to run each week

    Or, on a monthly increment you can specify a date or a day of the week that occurs within the month.

    Set the schedule for the job to run each month

    To finish, set the Start time. This is the time that the job starts at the specified interval. It uses the time zone configured for your USM Anywhere instance (default is UTC).

  12. Click Save.